Description
In the Linux kernel, the following vulnerability has been resolved:

NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers

flexfiles accepts NFSv4.0 data servers, but two NFSv4 code paths assume
the data server client has a session. Unlike NFSv4.1+, an NFSv4.0 client
has no session (clp->cl_session is NULL; it uses clp->cl_slot_tbl), so
I/O to a v4.0 flexfiles DS oopses:

- nfs4_init_ds_session() dereferences clp->cl_session->session_state
while seeding the DS lease. It also only seeds cl_lease_time when
NFS4_SESSION_INITING is set; without a session that never happens, so
cl_lease_time stays 0 and nfs4_renew_state() busy-loops, requeuing
every 5 seconds. Seed the lease whenever there is no session and
return before touching session state.

- ff_layout_async_handle_error_v4() dereferences
clp->cl_session->fc_slot_table on every DS I/O error. Fall back to the
v4.0 transport slot table (clp->cl_slot_tbl) when there is no session.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Apply patch
AI Analysis

Impact

The vulnerability is a NULL dereference in the Linux kernel’s NFSv4 implementation, specifically in flexfiles handling of NFSv4.0 data servers. When a client without a session pointer communicates with the server, the kernel dereferences a null session pointer during lease seeding and error handling, causing a crash. This permits an attacker to force a kernel panic, disrupting system availability and providing a denial‑of‑service vector.

Affected Systems

All Linux distributions that ship the Linux kernel without the applied kernel patch are potentially impacted. The issue existed in older kernel releases before the commit referenced in the advisory. Users running those kernels on any vendor’s Linux system—whether servers, desktops, or embedded devices—are at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% implies a low but present likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported. The likely attack vector is through network NFS traffic from a client using NFSv4.0, which may be exploitable remotely if the server’s NFS daemon is reachable. Given the lack of known exploits, the current risk to production systems is moderate, but the impact of a kernel crash is severe.

Generated by OpenCVE AI on September 20, 2026 at 02:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch applied in the reference commits.
  • If an immediate kernel upgrade is not feasible, disable NFSv4.0 support or block NFS traffic at the network perimeter.
  • Continuously monitor system logs for NFS errors or kernel panics that may indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers flexfiles accepts NFSv4.0 data servers, but two NFSv4 code paths assume the data server client has a session. Unlike NFSv4.1+, an NFSv4.0 client has no session (clp->cl_session is NULL; it uses clp->cl_slot_tbl), so I/O to a v4.0 flexfiles DS oopses: - nfs4_init_ds_session() dereferences clp->cl_session->session_state while seeding the DS lease. It also only seeds cl_lease_time when NFS4_SESSION_INITING is set; without a session that never happens, so cl_lease_time stays 0 and nfs4_renew_state() busy-loops, requeuing every 5 seconds. Seed the lease whenever there is no session and return before touching session state. - ff_layout_async_handle_error_v4() dereferences clp->cl_session->fc_slot_table on every DS I/O error. Fall back to the v4.0 transport slot table (clp->cl_slot_tbl) when there is no session.
Title NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:25.246Z

Reserved: 2026-09-11T19:38:34.789Z

Link: CVE-2026-90149

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:07.830

Modified: 2026-09-18T18:17:44.120

Link: CVE-2026-90149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:30:17Z

Weaknesses